Cryptoramic

Supplier readiness · PKI Consortium PQCMM

Know which suppliers to call first.

Your suppliers own part of your PQC timeline. Cryptoramic puts what their products contain beside what their readiness reports declare.

Supplier readiness and exposure
Cryptoramic supplier priorities showing PQCMM maturity, cryptographic exposure and installations.
Actual application · Illustrative assessment data

Observed findings and declared maturity.

Keep a supplier’s assessment and your observations distinct. Use both to decide which question to ask next.

Observed, from your scans

What the product actually ships

The cryptography inside each installed product, its known vulnerabilities, its policy findings and how many hosts run it.

Declared, by the supplier

What the supplier reports

PQC Maturity Model reports with their publisher, dates, scope and assurance, matched to the exact product and version.

Product and version evidence.

Cryptoramic matches available reports to identified products and versions, retaining the publisher, dates, scope and stated assurance. A report for one version does not establish readiness for another.

Model developed byPKI ConsortiumPQC Maturity Model
Readiness by version
Product versions with supplier-reported maturity, cryptographic exposure and host installations.
Actual application · Illustrative assessment data

Supplier questions and next actions.

Vendor priorities you can explain

Ranked by installed reach, known vulnerabilities, open findings and missing evidence, with the weighting shown.

Honest about gaps

Unreported means the evidence is missing, not that a product lacks PQC support. A report for one version never covers another.

Supplier campaigns in your plan

The program plan turns the list into supplier coverage, readiness requirements and priority campaigns.

Frequently asked questions

Does Unreported mean a supplier is not PQC ready?

No. It means no matching report was found for that product and version. Ask the supplier for the missing information. A missing report is different from a report showing a problem.

Does importing a report certify the supplier?

No. Importing stores the report; it does not independently check the supplier’s claims. Cryptoramic keeps the report’s coverage and assessment type visible, so you can distinguish a supplier’s self-assessment from an independent assessment.

Make your next supplier conversation specific.

Bring a product, an application or a supplier question. We will show how the evidence comes together.

Discuss your assessment

Product screenshot

Illustrative assessment data